Report
2026 Application Threat Landscape
Our annual analysis of the vulnerability classes and exploitation trends defining the year ahead.
Attack surfaces are consolidating around identity
Across the 3,200+ assessments we conducted last year, identity and access control failures overtook injection vulnerabilities as the most common path to critical impact. Broken object-level authorization in APIs alone accounted for nearly a third of critical findings.
As organizations decompose monoliths into microservices, the number of trust boundaries multiplies — and each one is a fresh opportunity for an authorization check to be missed or inconsistently applied.
Supply chain exposure keeps growing
Dependency-based findings rose sharply again this year, driven by CI/CD pipeline misconfiguration as much as vulnerable packages themselves. Attackers increasingly target the build pipeline rather than the shipped artifact.
Organizations with mature software bill-of-materials practices detected and remediated dependency risk significantly faster than those relying on point-in-time scans.
Cloud misconfiguration remains the quiet majority
Despite years of tooling investment, over-permissioned IAM roles and publicly exposed storage remain among the top initial access vectors we observe in red team engagements. Configuration drift, not initial deployment error, is usually the root cause.
What this means for 2026
Prioritize authorization testing for every new API endpoint before release. Treat your build pipeline as production infrastructure. And invest in continuous cloud posture monitoring, not annual audits — drift happens weekly, not yearly.
Keep Reading
More from Reports.
The State of Cloud Misconfiguration
A data-driven look at the IAM, storage, and network misconfigurations most commonly exploited in real intrusions.
Read the ReportRansomware Response Benchmarks
Detection and containment timing data from incident response engagements across 2025.
Read the ReportYour infrastructure is a target. Find out where before an adversary does.
Speak with our security engineers about a tailored assessment scoped to your environment, industry, and risk posture.
